LuferOS

forcedns_Magisk-kernelsu

3.0guide

Fuerza todo el tráfico DNS estándar (puerto 53) a usar 1.1.1.1 mediante iptables. Sobrescribe DNS de red. Compatible con Magisk/KernelSU.

★14 stars
•Networking & Proxies•by LuferOS•MIT•Updated Sep 14, 2026
Platforms:
✓ Magisk✓ KernelSU

Overview

Many Android applications (notably streaming clients, social platforms, and games) hardcode external DNS server IPs (such as Google Public DNS 8.8.8.8 or ISP fallback servers) directly into their network stacks. These applications intentionally bypass Android’s Private DNS (DNS-over-TLS) settings, leaking domain query logs to telemetry brokers and evading local ad-blocking policies.

Developed by LuferOS, ForceDNS Premium closes this privacy loophole at the kernel netfilter boundary. By deploying automated iptables NAT rules across all cellular and Wi-Fi network interfaces, ForceDNS captures all outbound UDP and TCP traffic directed at port 53 and forcibly redirects it to your verified secure DNS provider.

How Kernel Redirection Prevents Leaks

Traditional DNS changers create a local pseudo-VPN using Android’s VpnService. This approach consumes battery, creates status bar clutter, and prevents users from using actual VPN services.

ForceDNS operates at the system kernel layer:

  1. Packet Capture: When any application attempts to resolve a domain over standard port 53, the packet is trapped in the PREROUTING and OUTPUT iptables chains.
  2. Deterministic Rerouting: The destination address is rewritten to a secure resolver (such as Cloudflare 1.1.1.1 / 1.0.0.1 or AdGuard DNS).
  3. Transparent Delivery: The app receives the resolved IP address seamlessly, completely unaware that its hardcoded resolver was intercepted.
  4. NextDNS DoT: For advanced filtering, the module coordinates with Android’s native Private DNS engine to bind your custom NextDNS profile ID over encrypted TLS.

WebUI Configuration

ForceDNS includes an embedded WebUI interface compatible with Magisk and KernelSU:

  • Switch upstream DNS providers (Cloudflare, Quad9, AdGuard, Google, NextDNS) with a single tap.
  • Toggle redirection rules on or off dynamically.
  • Monitor active interface binding states.

Installation & Setup

  1. Verify that your root manager supports Magisk v24+ or KernelSU.
  2. Download and flash the forcedns_Magisk-kernelsu .zip archive.
  3. Reboot your device.
  4. Open your root manager’s module panel to launch the ForceDNS WebUI and select your preferred DNS resolver.
  5. Verify protection using an online DNS leak test tool; all queries will resolve exclusively through your configured upstream provider.